Description
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
References (12)
Core 12
Core References
Mitigation, Patch, Third Party Advisory
https://blog.hackeriet.no/perl-http-tiny-insecure-tls-default-affects-cpan-modules/
Exploit, Issue Tracking
https://github.com/andk/cpanpm/pull/175
Release Notes
https://metacpan.org/dist/CPAN/changes
Mailing List, Patch
https://www.openwall.com/lists/oss-security/2023/04/18/14
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240621-0007/
Mailing List, Patch mailing-list
http://www.openwall.com/lists/oss-security/2023/04/29/1
Mailing List, Patch mailing-list
http://www.openwall.com/lists/oss-security/2023/05/03/3
Mailing List mailing-list
http://www.openwall.com/lists/oss-security/2023/05/03/5
Mailing List mailing-list
http://www.openwall.com/lists/oss-security/2023/05/07/2
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BM6UW55CNFUTNGD5ZRKGUKKKFDJGMFHL/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LEGCEOKFJVBJ2QQ6S2H4NAEWTUERC7SB/
Scores
CVSS v3
8.1
EPSS
0.0156
EPSS Percentile
72.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-295
Status
published
Products (2)
cpanpm_project/cpanpm
< 2.35
perl/perl
< 5.38.0
Published
Apr 29, 2023
Tracked Since
Feb 18, 2026